3,612 karma · joined May 13, 2016
The machine: https://en.wikipedia.org/wiki/Memex
Audio gear isn't made to last long on batteries, it's made to be reliable for the hours a show typically lasts. I worked part-time as a sound tech (paid hobby) for 15+ years, and I never started a show without fresh batteries, regardless of what the indicators on the transmitters/receivers told me.
From what I remember (a few years old, things may have changed) they required devs to stage packages to a specific test env, packages were inspected not only for malware but also vulnerabilities before being released to the public.
NPM on the other hand... Write a package -> publish. Npm might scan for malware, they might do a few additional checks, but at least back when I looked into it nothing happened proactively.
And before you know it, you have a multitude of distributions to choose from, each with their own issues...
Fully agree on what you are saying, and my popcorn is ready for August when the penalties part of the AI Act comes into force. There is a grace period for two years for certain systems already on the market, but any new model introduced after August this year has to be compliant. AI Act+GDPR will be a great show to watch...
There already are, but only for Europeans through the GDPR.
In this case 23andMe is on the Data Privacy Framework list, so they have volunteered to follow the GDPR while still being based in the US. This is basically the same as a number of other GDPR cases, including the GDPR fine against Clearview AI. Fining 23andMe if they violate GDPR should be trivial in that case.
«This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to: (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union;»
So the GDPR applies. The EU can of course sanction violators outside, but given the current political climate it is likely to be more difficult than before.
I think the main point bob1029 was trying to make is that it can be worthwhile doing somehting in-house if the alternatives doesn't match the use-case, are too expensive or whatever else - but that you seriously need to consider if your architecture is the best way to solve the problem before going down that route.
That statement from Michael Eavis (founder of the festival) kind of hits home with a recent story from The Independent in how bands are settling for less, or even paying to play at the festival - as an investment. Being shown on the BBC as part of their coverage can make or break the experience (and their economy).
https://www.independent.co.uk/arts-entertainment/music/featu...
One of the biggest Norwegian banks were used as a cover for a scam in Portugal, involving 2500 ad posters distributed by advertising company JCDecaux, with QR-codes linking to scam sites. The ad campaign cost around 5M NOK ($~0.5 USD), and the victims were tricked into signing up for various loans and investment programs, with lots of extra fees added on top.
Get rid of any unwanted noise caused by gear or environment. Add a basic EQ - I'm using a 15-band one just to compensate for the room, the speakers, hearing loss and anything else that would impact the sound.
If only this was true... Injection has been on Owasp Top 10 since its inception, and is unlikely to go away anytime soon. Learning some techniques can be useful just to do quick assessments of basic attack vectors, and to really understand how you can protect yourself.
Wikipedia bases all its content on the following: "A topic is presumed to be suitable for a stand-alone article or list when it has received significant coverage in reliable sources that are independent of the subject."
This is flexible enough to allow a lot of stuff, but also causes endless debates, discussions and complaints when content is removed. This is (in my opinion) one of the things that actually give Wikipedia value. If everything is permitted, separating spam from actual content is hopeless.
Defining a scope for your application is a must; if you gain even the slightest popularity, every self-serving developer is going to try to piggyback on you. "See, my project is listed on xyz, therefore it's famous and hence I'm a rockstar."
-Do you want to include any project hosted anywhere? -Incomplete/unfinished projects? -Forks? -Do you want to limit yourself to particular licenses? -What about ecosystems such as PyPi, Nuget, npm and all the rest? Code is mainly hosted on github, but do you want to maintain any kind of relation between source and package?
I think this could be handy, both for finding alternatives if you have an issue with a library or if you're looking for "something" that does <abc>.
This only works for published dependencies, but based on a couple years experience it works really well. No issues with malware (so far), we don't let packages with known vulns into our codebases and we are notified if a vuln is discovered in something we use.